logo

Sandworm hackers use data wipers to disrupt Ukraine's grain sector

ID: c9e54391-a9d9-547f-ae1a-41014924e07d

STIX ID: report--c9e54391-a9d9-547f-ae1a-41014924e07d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-11-06

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

ESET reports that Russian state-backed APT Sandworm (APT44) conducted multiple destructive data-wiping campaigns in Ukraine between April and September 2025, targeting government, education, energy, logistics and the strategically important grain sector; the report also describes Iran-aligned activity using Go-based open-source wipers against Israeli infrastructure and notes initial access via UAC-0099 in some cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.